CVE Database
/

CVE-2018-14667

Back to search

CVE-2018-14667

Published: Nov 6, 2018

Modified: Oct 21, 2025

PUBLISHED

CVSS v3.0

9.8

CRITICAL

Description

The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain of java serialized objects via org.ajax4jsf.resource.UserResource$UriData.

VendorProductVersions

[UNKNOWN]

RichFaces

affected
affected 3.X through 3.3.4

Weaknesses (CWE)

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

References

RHSA-2018:3519
vendor-advisory
x_refsource_REDHAT
RHSA-2018:3581
vendor-advisory
x_refsource_REDHAT
RHSA-2018:3518
vendor-advisory
x_refsource_REDHAT
RHSA-2018:3517
vendor-advisory
x_refsource_REDHAT
1042037
vdb-entry
x_refsource_SECTRACK
20200313 RichFaces exploitation toolkit
mailing-list
x_refsource_FULLDISC

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now